CVE-2023-42838: Apple macOS
High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey 12.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Affected products
- Apple macOS: from 12.0, before 12.7.2 (fixed in 12.7.2); from 13.0, before 13.6.3 (fixed in 13.6.3); version 14.0 only
Published 2024-02-21. Last modified 2026-06-17.